CVE-2014-3537

Source
https://cve.org/CVERecord?id=CVE-2014-3537
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2014-3537.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2014-3537
Downstream
DEBIAN (1)
MGASA (1)
openSUSE (1)
RHBA (1)
RHSA (1)
SUSE (2)
UBUNTU (1)
Related
Withdrawn
2026-01-27T04:12:43Z
Published
2014-07-23T14:55:05Z
Modified
2026-04-16T01:41:52Z
Summary
[none]
Details

The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/.

References

Affected packages